Prompt Injection attack against LLM-integrated Applications

Атаки с внедрением промптов на приложения, интегрированные с большими языковыми моделями
Yang Liu, Gelei Deng, Yepang Liu, Yuekang Li, Kailong Wang, Tianwei Zhang, Yi Liu, Wang, Zihao, Wang, Xiaofeng, Wang, Haoyu, Yan Zheng, Zhang, Leo Yu
2023-06-08

HouYiLLM-integrated applicationsapplication prompt theftblack-box attackprompt injection attacks
Large Language Models (LLMs), renowned for their superior proficiency in language comprehension and generation, stimulate a vibrant ecosystem of applications around them. However, their extensive assimilation into various services introduces significant security risks. This study deconstructs the complexities and implications of prompt injection attacks on actual LLM-integrated applications. Initially, we conduct an exploratory analysis on ten commercial applications, highlighting the constraints of current attack strategies in practice. Prompted by these limitations, we subsequently formulate HouYi, a novel black-box prompt injection attack technique, which draws inspiration from traditional web injection attacks. HouYi is compartmentalized into three crucial elements: a seamlessly-incorporated pre-constructed prompt, an injection prompt inducing context partition, and a malicious payload designed to fulfill the attack objectives. Leveraging HouYi, we unveil previously unknown and severe attack outcomes, such as unrestricted arbitrary LLM usage and uncomplicated application prompt theft. We deploy HouYi on 36 actual LLM-integrated applications and discern 31 applications susceptible to prompt injection. 10 vendors have validated our discoveries, including Notion, which has the potential to impact millions of users. Our investigation illuminates both the possible risks of prompt injection attacks and the possible tactics for mitigation.
1
An exploratory analysis of ten commercial LLM-integrated applications exposed practical limitations in existing prompt injection attack strategies.
2
HouYi enables severe attack outcomes, including unrestricted arbitrary LLM usage and straightforward theft of application prompts.
3
HouYi is introduced as a black-box prompt injection technique combining a pre-constructed prompt, context-partitioning injection prompt, and malicious payload.
4
Ten vendors validated the reported vulnerabilities, including Notion, potentially affecting millions of users; the study also discusses mitigation tactics.
5
Testing 36 real-world LLM-integrated applications found 31 susceptible to prompt injection attacks.

actual LLM-integrated applications

vulnerability of these applications to prompt injection attacks and the resulting security impacts

Publication Details
Publication Date
2023-06-08
Journal
Publisher
ISSN
Cited by
84
Access Type
Author Information
Authors
Yang Liu
Gelei Deng
Yepang Liu
Yuekang Li
Kailong Wang
Tianwei Zhang
Yi Liu
Wang, Zihao
Wang, Xiaofeng
Wang, Haoyu
Yan Zheng
Zhang, Leo Yu
Explore further
Open the scid.ai AI chat with a ready-made request: it will find papers on a similar topic and help build a literature review.
Find similar papers in the chat
Make a presentation
100%